(Novell Issues Fix for Novell ZENworks Patch Management) PatchLink Update Temporary File Symlink Flaw in logtrimmer Lets Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1019310 |
|
SecurityTracker URL: http://securitytracker.com/id/1019310
|
|
CVE Reference:
CVE-2008-0525
(Links to External Site)
|
Date: Feb 6 2008
|
Impact:
Modification of system information, Modification of user information, User access via local system
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 6.2, 6.3, 6.4
|
Description:
Two vulnerabilities were reported in PatchLink Update. A local user can obtain elevated privileges on the target system. Novell ZENworks Patch Management is affected.
The UNIX client's 'logtrimmer' and 'rebootTask' scripts use temporary files in an unsafe manner. A local user can create a symbolic link (symlink) from a critical file on the target system to a temporary file to be used by PatchLink Update. When the script runs, the symlinked file will be overwritten by the script.
The logtrimmer script uses the 'patchlink.tmp' file and can be exploited to erase the contents of files on the target system.
The rebootTask script uses the '/tmp/plshutdown' file and can be exploit to execute arbitrary code.
Larry W. Cashdollar of Vapid Labs reported this vulnerability.
|
Impact:
A local user can obtain elevated privileges on the target system.
|
Solution:
Novell has issued a patch (LSA20080201 - Security Update for ZPM Update Agent for LUM 6.x) for Novell ZENworks Patch Management Update Agent, which is affected by these vulnerabilities.
The fix will also be included in ZPM Update Server 6.4 SP1.
The Novell advisory is available at:
https://secure-support.novell.com/KanisaPlatform/Publishing/18/3908994_f.SAL_Public.html
|
Cause:
Access control error, State error
|
Underlying OS:
Linux (Red Hat Enterprise), Linux (SuSE), UNIX (AIX), UNIX (HP/UX), UNIX (OS X), UNIX (Solaris - SunOS)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Wed, 6 Feb 2008 09:07:29 -0500
Subject: Novell ZENworks Patch Management
|
https://secure-support.novell.com/KanisaPlatform/Publishing/18/3908994_f.SAL_Public.html
CVE-2008-0525
|
|